IvantiÖÒ¸æ³Æ»¹ÓÐÈý¸öCSAÁãÈÕ·ì϶ÔÚ±»¹¥»÷ÕßÀûÓÃ

°ä²¼¹¦·ò 2024-10-10

1. IvantiÖÒ¸æ³Æ»¹ÓÐÈý¸öCSAÁãÈÕ·ì϶ÔÚ±»¹¥»÷ÕßÀûÓÃ


10ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úITÈí¼þ¹«Ë¾Ivanti½üÆÚ°ä²¼Á˰²È«¸üУ¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ½¨¸´Èý¸ö±»»ý¼«ÀûÓõÄÐÂÐÍÔÆ·þÎñÉ豸£¨CSA£©ÁãÈÕ·ì϶£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶±àºÅΪCVE-2024-9379¡¢CVE-2024-9380ºÍCVE-2024-9381¡£¡£¡£¡£¡£¡£¹¥»÷Õß½«ÕâЩ·ì϶Óë9Ô·ÝÒѽ¨²¹µÄÁíÒ»¸öCSAÁãÈÕ·ì϶£¨CVE-2024-8963£©½áºÏʹÓ㬣¬£¬£¬£¬£¬£¬Í¨¹ýSQL×¢Èë¡¢ºÅÁî×¢ÈëºÍõè¾¶±éÀúµÈ¼¿Á©£¬£¬£¬£¬£¬£¬£¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë²¢ÈÆ¹ý°²È«ÏÞ¶È¡£¡£¡£¡£¡£¡£IvantiÖÒ¸æ³Æ£¬£¬£¬£¬£¬£¬£¬ÔËÐÐCSA 4.6 patch 518¼°¸üÔç°æ±¾µÄ¿Í»§ÔÚ½áºÏÕâЩ·ì϶ʱ¿ÉÄÜÒÑÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬²¢½¨ÒéÊÜÓ°Ïì¿Í»§Éý¼¶µ½CSA 5.0.2°æ±¾ÒÔ³Á½¨É豸¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬£¬ÖÎÀíÔ±Ó¦ÀûÓÃEDR»òÆäËû°²È«Èí¼þ¾¯±¨£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°²é³­ÐµĻòÅú¸ÄºóµÄÖÎÀíÔ±Óû§À´¼ì²âÈëÇÖ¼£Ï󡣡£¡£¡£¡£¡£ÓÉÓÚCSA 4.6ÒÑÍ£²ú£¬£¬£¬£¬£¬£¬£¬ÈÔÔÚÔËÐд˰汾µÄ¿Í»§Ó¦¾¡¿ìÉý¼¶¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬CISAÒѽ«Óйطì϶Ôö³¤µ½ÒÑÖª±»ÀûÓ÷ì϶Ŀ¼ÖУ¬£¬£¬£¬£¬£¬£¬²¢ÒªÇóÁª¹ú»ú¹¹ÔÚ10ÔÂ10ÈÕǰ±£» £»£»£»£»£»£»£»¤Ò×Êܹ¥»÷µÄϵͳ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ivanti-warns-of-three-more-csa-zero-days-exploited-in-attacks/


2. ¿¨Î÷Å·ÔâÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬·þÎñÖжϲ¢Òý·¢Êý¾Ýй¶ÓÇÓô


10ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬£¬ÈÕ±¾¿Æ¼¼¾ÞÍ·¿¨Î÷Å·ÍÆËã»ú¹«Ë¾½üÆÚÔâ·êÁËÒ»Â·ÍøÂ簲ȫÊÂÎñ£¬£¬£¬£¬£¬£¬£¬ÆäÍøÂ类δ¾­ÊÚȨµÄÐÐΪÕß½Ó¼û£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂϵͳÖжϣ¬£¬£¬£¬£¬£¬£¬²¢Ó°ÏìÁ˲¿ÃÅ·þÎñ¡£¡£¡£¡£¡£¡ £¿£¿£¿£¿£¿¨Î÷Å·ÒÔÍó±í¡¢ÍÆËãÆ÷¡¢ÀÔì÷¡¢Ïà»úµÈµç×Ó²úÆ·ÎÅÃû£¬£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷¶ÔÆäÔì³ÉÁ˲»Ó×µÄÓ°Ïì¡£¡£¡£¡£¡£¡ £¿£¿£¿£¿£¿¨Î÷Å·ÔÚ²¼¸æÖÐÈ·ÈÏÁËÕâ´ÎÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬²¢°µÊ¾ÔÚÓë±í²¿×¨¼ÒºÏ×÷£¬£¬£¬£¬£¬£¬£¬ÒÔÈ·¶¨ÊÇ·ñÓÐÓ×ÎÒÊý¾Ý»òÆäËû»úÃÜÐÅÏ¢±»µÁ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Î´Ð¹Â©¸ü¶àϸ½Ú£¬£¬£¬£¬£¬£¬£¬Ò²Î´×¢Ã÷·þÎñÖжϵľßÌåÄÚÈÝ¡£¡£¡£¡£¡£¡ £¿£¿£¿£¿£¿¨Î÷Å·ÒÑÏòºÏÓõÄÊý¾Ý±£» £»£»£»£»£»£»£»¤»ú¹¹»ã±¨ÁË´ËÊÂÎñ£¬£¬£¬£¬£¬£¬£¬²¢²ÉÈ¡ÁËÏÞ¶È±í²¿ÈËÔ±½Ó¼ûµÄ´ëÊ©¡£¡£¡£¡£¡£¡£Ö»¹ÜÉÐδÓÐÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬£¬£¬£¬£¬£¬£¬µ«Õâ´ÎÊÂÎñ¶Ô¿¨Î÷Å·À´ËµÎÞÒÉÊÇÒ»´Î½ø¹¥¡£¡£¡£¡£¡£¡£Ô¼ÄªÒ»Äêǰ£¬£¬£¬£¬£¬£¬£¬¿¨Î÷Å·»¹ÔøÅû¶¹ýÁíһ·Êý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬Éæ¼°149¸ö¹ú¶ÈµÄ¿Í»§Êý¾Ý¡£¡£¡£¡£¡£¡£Õâ´Î×îеÄÍøÂ簲ȫÊÂÎñ²úÉúÔÚ¿¨Î÷Å·¼´½«Òò´ó¹æÄ£ÈËʳÁ×é¶øÔâ·ê½ü5000ÍòÃÀÔªÒìʱʱÐÔËðʧµÄ¼è¾Þʱ¿Ì£¬£¬£¬£¬£¬£¬£¬ÎÞÒɸø¸Ã¹«Ë¾´øÀ´Á˸ü´óµÄÌôÕ½¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/casio-reports-it-systems-failure-after-weekend-network-breach/


3. Awaken Likho APT×é֯ѡȡÐÂÕ½Êõ¹¥»÷¶íÂÞ˹»ú¹¹


10ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬£¬¿¨°Í˹»ù×êÑÐÈËÔ±½ÒʾÁËAwaken Likho APT×éÖ¯£¨±ðÃûCore Werewolf£©×Ô2021Äê7ÔÂÒÔÀ´Õë¶Ô¶íÂÞ˹µ±¾Ö»ú¹¹ºÍ¹¤ÒµÆóÒµÌáÒéµÄ×îй¥»÷¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÔÚ2024Äê6ÔµÄй¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬ÏÔÖøÅ¤×ªÁËÆäÈí¼þºÍ¼¼Êõ£¬£¬£¬£¬£¬£¬£¬´ÓÀûÓÃUltraVNCÄ £¿£¿£¿£¿£¿éתÏòʹÓúϷ¨µÄMeshCentralƽ̨´úÀíMeshAgent¡£¡£¡£¡£¡£¡£MeshCentral×÷ΪһÖÖ¿ªÔ´Ô¶³ÌÉ豸ÖÎÀí½â¾ö¹æ»®£¬£¬£¬£¬£¬£¬£¬±»¹¥»÷Õß·¸·¨ÀûÓÃÒÔ½ÚÔìÊÜϰȾϵͳ£¬£¬£¬£¬£¬£¬£¬Õâһת±äÔö³¤Á˹¥»÷µÄÒñ±ÎÐÔºÍÄѶȡ£¡£¡£¡£¡£¡ £¿£¿£¿£¿£¿¨°Í˹»ùÍŶӷ¢ÏÖ£¬£¬£¬£¬£¬£¬£¬Awaken Likhoͨ¹ýÍøÂç´¹µöµç×ÓÓʼþ´«²¼ÐÂÖ²È뷨ʽ£¬£¬£¬£¬£¬£¬£¬ÕâЩÓʼþÀûÓÃ7-Zip´´½¨µÄSFXÌåʽ·Ö·¢£¬£¬£¬£¬£¬£¬£¬ÄÚº¬¼Ù×°³ÉºÏ·¨ÏµÍ³·þÎñºÍºÅÁîÎļþµÄµö¶ü¡£¡£¡£¡£¡£¡£Ö²È뷨ʽÔËÐк󣬣¬£¬£¬£¬£¬£¬»áÆô¶¯MeshAgentºÍÒ»¸ö¸ß¶È»ìºÏµÄºÅÁîÎļþ£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚʵÏÖÓÆ¾ÃÐÔ½ÚÔì¡£¡£¡£¡£¡£¡£Í¨¹ý´´½¨´òË㹤×÷£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÈ·±£MeshAgentÄܳÁÐÂÏνӵ½ºÅÁîºÍ½ÚÔì·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬¸ÃÏνÓͨ¹ýWebSocketºÍ̸³ÉÁ¢£¬£¬£¬£¬£¬£¬£¬²¢ÀûÓÃHTTPS¼ÓÃÜ¡£¡£¡£¡£¡£¡£Awaken LikhoµÄÕâ´Î¹¥»÷»î¶¯ÓëÒÔÍùÒ»Ö£¬£¬£¬£¬£¬£¬£¬Ö¸±êÈÔÊǶíÂÞ˹µ±¾Ö»ú¹¹¡¢³Ð°üÉ̺͹¤ÒµÆóÒµ¡£¡£¡£¡£¡£¡£


https://securityonline.info/new-campaign-by-awaken-likho-apt-group-changes-in-software-and-techniques/


4. »¥ÁªÍøµµ°¸¹ÝÔâÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬3100ÍòÓû§ÐÅÏ¢±»µÁ


10ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬£¬»¥ÁªÍøµµ°¸¹ÝµÄ¡°Wayback Machine¡±½üÆÚÔâ·êÁËÑϳÁµÄÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£Ò»ÃûÍþвÐÐΪÕ߳ɹ¦ÈëÇÖ¸ÃÍøÕ¾£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡ÁËÔ̺¬3100ÍòÌõΨһ¼Í¼µÄÓû§Éí·ÝÑéÖ¤Êý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýJavaScript¾¯±¨Ïòarchive.orgµÄ½Ó¼ûÕßÐû¸æÁËÕâÒ»ÈëÇÖ¡£¡£¡£¡£¡£¡£¸Ã¾¯±¨»¹Ìá¼°ÁËTroy Hunt´´½¨µÄHave I Been Pwned£¨HIBP£©Êý¾Ýй¶֪ͨ·þÎñ£¬£¬£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÒÑÓë¸Ã·þÎñ¹²ÏíÁ˱»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£±»µÁµÄÊý¾Ý¿âÃûΪ¡°ia_users.sql¡±£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»¸ö6.4GBµÄSQLÎļþ£¬£¬£¬£¬£¬£¬£¬Ô̺¬×¢²á³ÉÔ±µÄÉí·ÝÑéÖ¤ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Èçµç×ÓÓʼþµØÖ·¡¢ÆÁÄ»Ãû³Æ¡¢ÃÜÂë¸ü¸Ä¹¦·ò´Á¡¢Bcrypt¹þÏ£ÃÜÂëµÈ¡£¡£¡£¡£¡£¡£¾ÝHIBPµÄÊ×´´È˺àÌØÐ¹Â©£¬£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÖÐÓÐ3100Íò¸öΨһµç×ÓÓʼþµØÖ·£¬£¬£¬£¬£¬£¬£¬ÆäÖкܶàÒѶ©ÔÄHIBPµÄÊý¾Ýй¶֪ͨ·þÎñ¡£¡£¡£¡£¡£¡£ÕâЩÊý¾Ý½«ºÜ¿ì±»Ôö³¤µ½HIBPÖУ¬£¬£¬£¬£¬£¬£¬ÒÔ±ãÓû§Äܹ»²éÎÊËûÃǵÄÊý¾ÝÊÇ·ñÔÚÕâ´Îй¶Öб»Ð¹Â¶¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔÍþвÐÐΪÕßÊÇÈôºÎÇÖÈ뻥ÁªÍøµµ°¸¹ÝµÄ£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÊÇ·ñÓÐÆäËûÊý¾Ý±»µÁ¡£¡£¡£¡£¡£¡£¶ø¾ÍÔÚ½ñÌìÔçЩʱ³½£¬£¬£¬£¬£¬£¬£¬»¥ÁªÍøµµ°¸¹Ý»¹Ôâ·êÁËDDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬BlackMetaºÚ¿Í×éÖ¯ÒÑÐû³Æ¶Ô´ËÕÆ¹Ü£¬£¬£¬£¬£¬£¬£¬²¢°µÊ¾½«½øÐиü¶à¹¥»÷¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/internet-archive-hacked-data-breach-impacts-31-million-users/


5. Å·ÑǶà¹ú³¬2.8ÍòÈËÔâ¼ÓÃÜÇ®±ÒÇÔÈ¡¶ñÒâÈí¼þ¹¥»÷


10ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬£¬½üÆÚһ·´ó¹æÄ£¼ÓÃÜÇ®±ÒÇÔÈ¡¶ñÒâÈí¼þ»î¶¯Ó°ÏìÁ˶íÂÞ˹¡¢ÍÁ¶úÆä¡¢ÎÚ¿ËÀ¼¼°Å·ÑǵØÓòÆäËû¹ú¶ÈµÄ³¬¹ý28,000ÈË¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Í¨¹ý¼Ù×°³ÉºÏ·¨Èí¼þ£¬£¬£¬£¬£¬£¬£¬ÔÚYouTubeÊÓÆµºÍڲƭÐÔGitHub´æ´¢¿âÉϽøÐÐÍÆ¹ã£¬£¬£¬£¬£¬£¬£¬ÓÕµ¼Êܺ¦ÕßÏÂÔØÊÜÃÜÂë±£» £»£»£»£»£»£»£»¤µÄµµ°¸²¢Æô¶¯Ï°È¾¡£¡£¡£¡£¡£¡£¾ÝÍøÂ簲ȫ¹«Ë¾Dr. Web³Æ£¬£¬£¬£¬£¬£¬£¬¾ø´óÎÞÊýÊܺ¦ÕßÊǶíÂÞ˹¾ÓÃñ£¬£¬£¬£¬£¬£¬£¬Í¬Ê±°×¶íÂÞ˹¡¢ÎÚ×ȱð¿Ë˹̹¡¢¹þÈø¿Ë˹̹¡¢ÎÚ¿ËÀ¼¡¢¼ª¶û¼ªË¹Ë¹Ì¹ºÍÍÁ¶úÆäÒ²³öÏÖ´óÁ¿Ï°È¾¡£¡£¡£¡£¡£¡£¶ñÒâÈí¼þÀûÓöàÖÖ¼¿Á©ºýŪÓû§ÏÂÔØ£¬£¬£¬£¬£¬£¬£¬Ò»µ©Ï°È¾£¬£¬£¬£¬£¬£¬£¬»á²é³­µ÷ÊÔ¹¤¾ß¡¢ÌáÈ¡ËùÐèÎļþ¡¢Åú¸ÄWindows×¢²á±íÒÔʵÏÖÓÆ¾ÃÐÔ£¬£¬£¬£¬£¬£¬£¬²¢½Ù³ÖºÏ·¨µÄWindowsϵͳ·þÎñºÍä¯ÀÀÆ÷¸üйý³Ì¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ»¹»áÍøÂçϵͳÐÅÏ¢²¢Í¨¹ýTelegram»úеÈËÇÔÈ¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬Í¶·ÅSilentCryptoMinerÍÚ¾ò¼ÓÃÜÇ®±Ò£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°³äÈμô¼­Æ÷¼à¶½²¢´úÌæWindows¼ôÌù°åÖеÄÇ®°üµØÖ·¡£¡£¡£¡£¡£¡£Dr. Web·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬½öClipper¾Í½Ù³ÖÁ˼ÛÖµ6,000ÃÀÔªµÄÂòÂô¡£¡£¡£¡£¡£¡£ÎªÔ¤·À²ÆÕþËðʧ£¬£¬£¬£¬£¬£¬£¬½¨Òé´Ó¹Ù·½ÍøÕ¾ÏÂÔØÈí¼þ£¬£¬£¬£¬£¬£¬£¬²¢ÉóÉ÷¶Ô´ýYouTube»òGitHubÉϵÄÁ´½Ó¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/cryptocurrency/crypto-stealing-malware-campaign-infects-28-000-people/


6. ÃÀ˾·¨²¿Óë΢ÈíÁªÊÖ²é»ñ°ÙÓà¶íÂÞ˹ºÚ¿ÍÍøÂç´¹µöÍøÕ¾


10ÔÂ4ÈÕ£¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú˾·¨²¿ºÍ΢Èí½áºÏÐж¯£¬£¬£¬£¬£¬£¬£¬³É¹¦²é»ñÁË100¶à¸öÓɶíÂÞ˹ºÚ¿ÍÓÃÓÚÕë¶ÔÃÀ¹ú½øÐÐÍøÂç´¹µö»î¶¯µÄÍøÕ¾¡£¡£¡£¡£¡£¡£Õâ´ÎÐж¯Ö¼ÔÚ×èÖ¹¹ú¶ÈÖ§³ÖµÄÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬±£» £»£»£»£»£»£»£»¤ÃÀ¹úµÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£±»²é·âµÄÓòÃûÓÉÃûΪCallisto GroupµÄ×é֯ʹÓ㬣¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ÊǶíÂÞ˹Áª¹ú°²È«²¿ÃÅÊôµÄÐж¯µ¥Ôª£¬£¬£¬£¬£¬£¬£¬±»Ö¸¿Ø²ß¶¯Óã²æÊ½ÍøÂç´¹µö»î¶¯£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚºýŪÊÕ¼þÈËй¶µÇ¼ʹ´¦£¬£¬£¬£¬£¬£¬£¬Î´¾­ÊÚȨ½Ó¼ûµÐÔÖʵÌåºÍÆäËû¸ß¼ÛÖµÖ¸±êµÄ»úÃÜÐÅÏ¢¡£¡£¡£¡£¡£¡£Î¢ÈíÔÚÐж¯ÖвûÑïÁ˹ؼü×÷Ó㬣¬£¬£¬£¬£¬£¬ÌáÆðÁËÃñÊÂËßËÏ£¬£¬£¬£¬£¬£¬£¬ÒªÇó²é·âÓëCallisto GroupÓйØÁªµÄ66¸öÓòÃû¡£¡£¡£¡£¡£¡£Õâ´ÎÐж¯²»½ö·ÛËéÁËÏÖÓÐÔËÓªºÍ»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬»¹Ïò±í¹úµÐÊÖºÍÃÀ¹ú¹úÄÚÃñ¶à·¢³öÁËÃ÷È·µÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Åú×¢¶íÂÞ˹ÊÇÒ»¸öÕæÕýµÄÍøÂçÐж¯µÐÊÖ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÐж¯Ò²Õ¹Ê¾Á˵±¾ÖºÍ˽Ӫ²¿ÃÅÖ®¼ä³ÖÐøºÏ×÷µÄ³ÁÒªÐÔ£¬£¬£¬£¬£¬£¬£¬Äܹ»¹²Í¬¸ü¿ìµØ¶ôÔìÍøÂç·¸×ï¡£¡£¡£¡£¡£¡£


https://hackread.com/doj-microsoft-seize-russian-phishing-sites-target-us/